The odd saga of CVE-2012-5639
The odd saga of CVE-2012-5639
Posted Jan 10, 2024 8:49 UTC (Wed) by NYKevin (subscriber, #129325)In reply to: The odd saga of CVE-2012-5639 by fwiesweg
Parent article: The odd saga of CVE-2012-5639
But: Browsers automatically load external content when requested to do so, and you don't see anyone filing a CVE for that behavior by itself. External content loading is one of the oldest bits of browser functionality, having been implemented very early on in the web's history. So it's difficult to argue that this is not a desirable feature for a document-sharing application. And yes, there are privacy implications, but IMHO those are best solved through some combination of (legal) regulation and selective blocking, not by configuring the software to be broken by default.
